Bug 2521847 - Kernel panic at skb_clone on 7.1.8-200.fc44.x86_64 during a Google Meet call with a screen being shared, while Podman containers, VSCode, and Slack were running in the background.
Summary: Kernel panic at skb_clone on 7.1.8-200.fc44.x86_64 during a Google Meet call ...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: kernel
Version: 44
Hardware: x86_64
OS: Linux
unspecified
medium
Target Milestone: ---
Assignee: Justin M. Forbes
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-24 12:47 UTC by Dalibor Kricka
Modified: 2026-09-04 01:28 UTC (History)
15 users (show)

Fixed In Version: kernel-7.1.13-200.fc44 kernel-7.1.13-100.fc43
Clone Of:
Environment:
Last Closed: 2026-09-04 01:11:43 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Dalibor Kricka 2026-08-24 12:47:17 UTC
1. Please describe the problem:
The whole system crashed with a black screen, error trace QR-Code, and the title "Kernel panic! Fatal exception in interupt" on 7.1.8-200.fc44.x86_64 during a Google Meet call with a screen being shared, while Podman containers, VSCode, and Slack were running in the background.


2. What is the Version-Release number of the kernel:
7.1.8-200.fc44.x86_64


3. Did it work previously in Fedora? If so, what kernel version did the issue
   *first* appear?  Old kernels are available for download at
   https://koji.fedoraproject.org/koji/packageinfo?packageID=8 :
First time this happened to me.


4. Can you reproduce this issue? If so, please provide the steps to reproduce
   the issue below:
I did not managed to reproduce it.


5. Does this problem occur with the latest Rawhide kernel? To install the
   Rawhide kernel, run ``sudo dnf install fedora-repos-rawhide`` followed by
   ``sudo dnf update --enablerepo=rawhide kernel``:
I did not managed to reproduce it.


6. Are you running any modules that not shipped with directly Fedora's kernel?:
I don't think so.


7. Please attach the kernel logs. You can get the complete kernel log
   for a boot with ``journalctl --no-hostname -k > dmesg.txt``. If the
   issue occurred on a previous boot, use the journalctl ``-b`` flag.

Linux kernel version: 7.1.8-200.fc44.x86_64
Architecture: x86_64
Fedora version: 44

[522705.613410] RSP: 002b:00007ffdc6785ee0 EFLAGS: 00000202 ORIG_RAX: 0000000000000001
[522705.613412] RAX: ffffffffffffffda RBX: 000055eb6b88fb90 RCX: 00007fe66767654e
[522705.613413] RDX: 0000000000000027 RSI: 000055eb6b81bd50 RDI: 0000000000000010
[522705.613414] RBP: 00007ffdc6785ef0 R08: 0000000000000000 R09: 0000000000000000
[522705.613415] R10: 0000000000000000 R11: 0000000000000202 R12: 0000000000000010
[522705.613417] R13: 0000000000000002 R14: 000055eb6b81bca0 R15: 000055eb6b81bd50
[522705.613419]  </TASK>
[522705.613420] Modules linked in: nft_nat veth bridge stp llc tun hid_sensor_hub overlay snd_usb_audio snd_usbmidi_lib snd_ump snd_rawmidi typec_displayport nft_masq uinput rfcomm nf_conntrack_netlink snd_seq_dummy snd_hrtimer xt_CT ip_set_hash_net ip_set xt_connmark xt_TCPMSS xt_MASQUERADE xt_mark xt_conntrack nft_compat wireguard libcurve25519 ip6_udp_tunnel udp_tunnel nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 nf_tables nfnetlink qrtr uhid bnep sunrpc binfmt_misc snd_soc_skl_hda_dsp snd_soc_intel_sof_board_helpers snd_soc_intel_hda_dsp_common snd_sof_probes vfat fat snd_hda_codec_intelhdmi snd_hda_codec_hdmi snd_hda_codec_alc269 snd_hda_codec_realtek_lib snd_hda_scodec_component snd_hda_codec_generic snd_soc_dmic snd_hda_intel snd_sof_pci_intel_mtl snd_sof_intel_hda_generic soundwire_intel snd_sof_intel_hda_sdw_bpt iwlmld r8153_ecm
[522705.613465]  snd_sof_intel_hda_common cdc_ether usbnet snd_soc_hdac_hda snd_sof_intel_hda_mlink snd_sof_intel_hda mac80211 intel_rapl_msr soundwire_cadence snd_sof_pci intel_uncore_frequency snd_sof_xtensa_dsp intel_uncore_frequency_common snd_sof x86_pkg_temp_thermal intel_powerclamp coretemp snd_sof_utils snd_hda_ext_core kvm_intel snd_hda_codec libarc4 snd_hda_core snd_intel_dspcfg snd_intel_sdw_acpi kvm snd_soc_acpi_intel_match snd_soc_acpi_intel_sdca_quirks soundwire_generic_allocation iwlwifi snd_soc_sdw_utils snd_hda_scodec_tas2781_i2c snd_soc_acpi uvcvideo snd_hwdep btusb snd_hda_scodec_tas2781 soundwire_bus btmtk uvc snd_soc_tas2781_comlib_i2c videobuf2_vmalloc snd_soc_tas2781_fmwlib snd_soc_sdca spi_nor videobuf2_memops btrtl irqbypass snd_soc_tas2781_comlib videobuf2_v4l2 btbcm iTCO_wdt rapl crc8 btintel intel_cstate snd_ctl_led mei_gsc_proxy mei_wdt spd5118 mtd intel_pmc_bxt snd_soc_core r8152 think_lmi videobuf2_common intel_uncore cfg80211 bluetooth mii firmware_attributes_class snd_compress videodev
[522705.613510]  wmi_bmof ac97_bus processor_thermal_device_pci pcspkr processor_thermal_device snd_pcm_dmaengine snd_seq thinkpad_acpi processor_thermal_wt_hint mc snd_seq_device sparse_keymap platform_temperature_control snd_pcm rfkill processor_thermal_soc_slider int3403_thermal processor_thermal_rfim mei_me int3400_thermal snd_timer intel_pmc_core processor_thermal_rapl acpi_thermal_rel intel_rapl_common snd mei processor_thermal_wt_req i2c_i801 pmt_telemetry spi_intel_pci processor_thermal_power_floor pmt_discovery joydev soundcore i2c_smbus acpi_tad spi_intel acpi_pad pmt_class intel_pmc_ssram_telemetry processor_thermal_mbox idma64 igen6_edac int340x_thermal_zone zram lz4hc_compress lz4_compress dm_crypt hid_logitech_hidpp hid_logitech_dj xe drm_ttm_helper drm_suballoc_helper gpu_sched drm_gpuvm drm_exec drm_gpusvm_helper i915 ucsi_acpi drm_buddy typec_ucsi i2c_algo_bit ttm typec hid_multitouch rtsx_pci_sdmmc nvme mmc_core drm_display_helper thunderbolt i2c_hid_acpi i2c_hid nvme_core intel_vpu video rtsx_pci cec
[522705.613559]  nvme_keyring wmi nvme_auth pinctrl_meteorlake intel_vsec serio_raw fuse ntsync i2c_dev
[522705.613569] ---[ end trace 0000000000000000 ]---
[522705.613572] RIP: 0010:skb_clone+0x159/0x1e0
[522705.613576] Code: 48 89 90 d0 00 00 00 8b 93 d8 00 00 00 c7 80 dc 00 00 00 01 00 00 00 89 90 d8 00 00 00 8b 93 c0 00 00 00 48 03 93 c8 00 00 00 <f0> ff 42 20 80 4b 7e 01 48 83 c4 08 5b c3 cc cc cc cc 48 8b 93 d0
[522705.613578] RSP: 0018:ffffcb72004fcd50 EFLAGS: 00010286
[522705.613579] RAX: ffff8a7543afb500 RBX: ffff8a7554ffad00 RCX: 0000000000000020
[522705.613580] RDX: ffff8a73736d279f RSI: 0000000000000003 RDI: ffff8a6e63490f00
[522705.613582] RBP: ffffffff91fc9900 R08: 00000000ffffff01 R09: ffff8a7543afb500
[522705.613583] R10: ffff8a6dc4349120 R11: ffff8a6e63490f00 R12: ffff8a73736d272d
[522705.613584] R13: 0000000000000000 R14: 000000000000001c R15: ffff8a7554ffad00
[522705.613585] FS:  00007fe668566480(0000) GS:ffff8a7d5e415000(0000) knlGS:0000000000000000
[522705.613586] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[522705.613588] CR2: 00007fb8de35a000 CR3: 0000000112919004 CR4: 0000000000f72ef0
[522705.613589] PKRU: 55555554
[522705.613590] Kernel panic - not syncing: Fatal exception in interrupt
[522705.613758] Kernel Offset: 0xd200000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff)


Reproducible: Always

Comment 1 junjie.cao 2026-09-01 00:59:41 UTC
Same instruction as bug 2521546, decoded from your inline Oops: the
Code bytes at skb_clone+0x159 are "f0 ff 42 20" = lock incl 0x20(%rdx),
the atomic_inc on skb_shinfo(skb)->dataref, with RDX =
ffff8a73736d279f. That puts dataref at ...27bf, byte 63 of a 64-byte
cache line, so the 4-byte atomic straddles two lines: a kernel-mode
split lock, fatal on Intel. skb->head is misaligned by 0x1f because it
came from a page_pool fragment at an odd offset -- your module list has
veth/bridge (Podman), and veth's skb_pp_cow_data() is one of the callers
that leaves the pool's fragment offset odd.

Upstream fix, in net.git with Cc: stable:
https://git.kernel.org/netdev/net/c/dc0df5a0c62c
Fedora 44 backport MR:
https://gitlab.com/cki-project/kernel-ark/-/merge_requests/4730

Workaround until it lands: boot with split_lock_detect=off.

Comment 2 Fedora Update System 2026-09-02 17:55:19 UTC
FEDORA-2026-a7b1ccd14c (kernel-7.1.13-100.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-a7b1ccd14c

Comment 3 Fedora Update System 2026-09-02 17:56:00 UTC
FEDORA-2026-0d885c0533 (kernel-7.1.13-200.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-0d885c0533

Comment 4 Fedora Update System 2026-09-03 01:39:06 UTC
FEDORA-2026-0d885c0533 has been pushed to the Fedora 44 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-0d885c0533`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-0d885c0533

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 5 Fedora Update System 2026-09-03 01:54:45 UTC
FEDORA-2026-a7b1ccd14c has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-a7b1ccd14c`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-a7b1ccd14c

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 6 Fedora Update System 2026-09-04 01:11:43 UTC
FEDORA-2026-0d885c0533 (kernel-7.1.13-200.fc44) has been pushed to the Fedora 44 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 7 Fedora Update System 2026-09-04 01:28:06 UTC
FEDORA-2026-a7b1ccd14c (kernel-7.1.13-100.fc43) has been pushed to the Fedora 43 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.